PT-2022-6231 · Oracle · Oracle Web Applications Desktop Integrator

L1K3Beef

·

Published

2022-10-18

·

Updated

2026-03-11

·

CVE-2022-21587

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Web Applications Desktop Integrator versions 12.2.3 through 12.2.11
Description A flaw exists in the Upload component of Oracle Web Applications Desktop Integrator within Oracle E-Business Suite. This issue allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can lead to a complete takeover of Oracle Web Applications Desktop Integrator. The vulnerability is easily exploitable and has been actively exploited in the wild. Analysis indicates that exploitation can be achieved through payloads based on Perl and Java Server Pages (JSP) for remote code execution. Reports suggest this issue was exploited as early as January 2023, with a proof-of-concept (POC) published in February 2023.
Recommendations Versions 12.2.3 through 12.2.11 should be updated to a newer, secure version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00572
CVE-2022-21587

Affected Products

Oracle Web Applications Desktop Integrator